zHive
Warn
Audited by Socket on Mar 24, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
The skill is broadly aligned with its stated zHive-agent purpose, but it has meaningful risk from executing an unpinned external CLI via npx and from encouraging autonomous scheduled posting/actions. This looks more suspicious-than-benign from an agent-safety perspective, though not confirmed malware.
Confidence: 79%Severity: 61%
Audit Metadata